Oracle Solaris vulnerabilities

549 known vulnerabilities affecting oracle/solaris.

Total CVEs
549
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
8
Severity breakdown
CRITICAL45HIGH116MEDIUM285LOW103

Vulnerabilities

Page 6 of 28
CVE-2019-2545MEDIUMCVSS 4.0v10v112019-01-16
CVE-2019-2545 [MEDIUM] CVE-2019-2545: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LD Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDoms IO). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability c
nvd
CVE-2019-2543MEDIUMCVSS 5.3v10v112019-01-16
CVE-2019-2543 [MEDIUM] CVE-2019-2543: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via KSSL to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2019-2544MEDIUMCVSS 4.0v10v112019-01-16
CVE-2019-2544 [MEDIUM] CVE-2019-2544: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can
nvd
CVE-2018-20685MEDIUMCVSS 5.3Exploitedv102019-01-10
CVE-2018-20685 [MEDIUM] CWE-863 CVE-2018-20685: In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrict In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
nvd
CVE-2018-3275HIGHCVSS 7.4v11.32018-10-17
CVE-2018-3275 [HIGH] CVE-2018-3275: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LibKMIP). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LibKMIP). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized creation, del
nvd
CVE-2018-3273HIGHCVSS 8.1v11.32018-10-17
CVE-2018-3273 [HIGH] CVE-2018-3273: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Ad Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon (RAD)). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks require human interaction from a pers
nvd
CVE-2018-3265MEDIUMCVSS 4.9v11.32018-10-17
CVE-2018-3265 [MEDIUM] CVE-2018-3265: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). T Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2018-3268MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3268 [MEDIUM] CVE-2018-3268: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partia
nvd
CVE-2018-3263MEDIUMCVSS 5.6v11.32018-10-17
CVE-2018-3263 [MEDIUM] CVE-2018-3263: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2018-3271MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3271 [MEDIUM] CVE-2018-3271: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. While the vulnerability is in Solaris, attacks may significan
nvd
CVE-2018-3274MEDIUMCVSS 5.7v11.32018-10-17
CVE-2018-3274 [MEDIUM] CVE-2018-3274: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Successful atta
nvd
CVE-2018-3269MEDIUMCVSS 4.3v11.32018-10-17
CVE-2018-3269 [MEDIUM] CVE-2018-3269: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial
nvd
CVE-2018-3264MEDIUMCVSS 4.4v11.32018-10-17
CVE-2018-3264 [MEDIUM] CVE-2018-3264: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized upd
nvd
CVE-2018-3267MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3267 [MEDIUM] CVE-2018-3267: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via FTP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Sola
nvd
CVE-2018-3172MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3172 [MEDIUM] CVE-2018-3172: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Sup Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Supported versions that are affected are 10 and 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via Portmap v3 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2018-3272MEDIUMCVSS 6.2v11.32018-10-17
CVE-2018-3272 [MEDIUM] CVE-2018-3272: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones Virtualized NIC Driver). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability
nvd
CVE-2018-2922LOWCVSS 2.5v11.32018-10-17
CVE-2018-2922 [LOW] CVE-2018-2922: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2018-3266LOWCVSS 3.9v11.32018-10-17
CVE-2018-3266 [LOW] CVE-2018-3266: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2018-3270LOWCVSS 1.8v11.32018-10-17
CVE-2018-3270 [LOW] CVE-2018-3270: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than t
nvd
CVE-2018-2928HIGHCVSS 8.1v11.32018-07-18
CVE-2018-2928 [HIGH] CVE-2018-2928: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RAD). The Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RAD). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Suc
nvd